[CLSA-2026:1790243751] pcs: Fix of 10 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-24 09:56:11 UTC
Description:
- CVE-2025-46727: unbounded query parsing in bundled rack; a body of repeated keys was parsed in full, exhausting memory. Capped by rack's new query bytesize and parameter-count limits, which pcsd turns into an HTTP 400 - CVE-2025-59830: the same unbounded query parse reached through ';' separated query strings, which rack's parameter counter did not count - CVE-2025-61770: multipart parsing in bundled rack read the whole request body searching for a boundary that never arrived - CVE-2025-61771: multipart parsing in bundled rack retained an unbounded non-file field in memory - CVE-2025-61772: multipart mime part headers in bundled rack were read with no size limit - CVE-2025-61919: Rack::Request#POST read the entire request body before any limit applied, so a 64 MB body was fully buffered - CVE-2024-49761: quadratic regular expression in bundled rexml BaseParser#unnormalize; a long run of zeros in a hex character reference made the parser hang - CVE-2024-52804: quadratic cookie unquoting in bundled tornado _unquote_cookie, which rescanned the value from each escape - CVE-2025-47287: malformed multipart/form-data in bundled tornado logged a warning per bad part instead of rejecting the request, flooding the log - CVE-2026-31958: unbounded part count and part header size in bundled tornado multipart parsing - Stop forwarding client HTTP headers from the Tornado front end to the Ruby part of pcsd, which only ever needed the cookie and the content type
Updated packages:
  • pcs-0.10.18-2.el8.tuxcare.els1.x86_64.rpm
    sha:e6e27886422aabe31cc9639e783446bc8449d11615f72f6188b9fa38265c2cbb
  • pcs-snmp-0.10.18-2.el8.tuxcare.els1.x86_64.rpm
    sha:08b1548ad40ef09e5838a445fd0ae6a41f46d046eb05ffb3e7a3c206c856e6a5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.